Acceptable Use Policy
Version 1.0 · Effective 19 August 2026
This Acceptable Use Policy (AUP) applies to every SimpleDiagrams Cloud account, diagram, viewer, API request, integration, and agent operation. It forms part of the SimpleDiagrams Cloud Terms. It does not govern SimpleDiagrams Desktop, which is separately sold under the applicable App Store terms. Customer is responsible for its users, credentials, integrations, agents, Customer Content, and broadly shared diagrams.
1. Use the Service for its intended purpose
SimpleDiagrams is for authoring and viewing diagrams and setting current visual state. It is read-only with respect to the equipment or source systems being represented. You must not use it as an alarm, emergency-response system, medical device, safety system, life-support system, autonomous controller, or sole basis for a safety-critical, financial, legal, or operational decision.
2. Prohibited unlawful or harmful activity
You must not use the Service to:
- violate a law, regulation, court order, sanction, or another person's rights;
- facilitate violence, exploitation, trafficking, fraud, extortion, or other serious harm;
- harass, threaten, defame, impersonate, deceive, or invade another person's privacy;
- publish child sexual abuse material or any sexual content involving a minor;
- infringe copyright, trademark, design, confidentiality, privacy, or other rights;
- send spam, phishing, malware, or unsolicited bulk communications;
- misrepresent live state, system health, identity, authority, or data provenance; or
- circumvent export controls or use the Service for a prohibited sanctioned party or location.
3. Prohibited data
Do not submit or expose through the Service:
- passwords, private keys, access tokens, payment-card data, or authentication secrets;
- protected health information, biometric identifiers, government identification numbers, highly sensitive financial data, or special-category personal data;
- classified information, controlled technical data, or information whose storage or international processing would violate export or national-security law;
- exact operational details of critical infrastructure where Customer lacks authority or appropriate safeguards; or
- data subject to a legal or contractual security standard the Service has not expressly agreed in writing to support.
The Service is designed for current diagram state, not personal profiling or sensitive record storage. If an ordinary equipment label or state value incidentally identifies a person, Customer must minimise it and meet applicable privacy obligations.
4. Security and service integrity
You must not:
- probe, scan, or test a vulnerability without our prior written authorisation;
- access or attempt to access another organisation, diagram, account, or credential;
- defeat authentication, authorisation, visibility, billing, quota, or rate controls;
- introduce malware, destructive code, denial-of-service traffic, or abusive payloads;
- interfere with availability, integrity, logging, or another customer's use;
- scrape, enumerate, or bulk-copy accounts, broadly shared diagrams, shapes, or libraries;
- use multiple accounts, organisations, IP addresses, or credentials to evade a limit; or
- publish a credential, secret, exploit, or vulnerability before coordinated remediation.
Good-faith security research must be agreed in writing and stay within the authorised scope. Report suspected vulnerabilities to support@simplediagrams.com and do not access Customer Content beyond what is necessary to demonstrate the issue.
5. APIs, automation, and agents
Automated use is permitted only through documented interfaces and authorised browser functions. Keep machine credentials secret and scoped, respect revision and idempotency requirements, identify the correct organisation and diagram, and obey payload, monthly, per-minute, concurrency, and other limits. Do not create retry storms or poll faster than documented.
The current MCP agent interface permits inspection of existing diagrams and updates to enabled current shape properties, subject to the principal's permissions and plan entitlement. It does not create or delete diagrams or shapes, change layout or configuration, or otherwise author a diagram. Other automated operations are permitted only where a documented interface supports them and the principal is authorised. You remain responsible for reviewing agent actions and source mappings. Do not instruct an agent to discover or manipulate raw Excalidraw internals, credentials, other tenants, or non-public APIs.
6. Shape, renderer, and content safety
You must have rights to each shape, image, font, or other asset that you submit or create through supported Service features. This does not promise support for uploads, custom shape definitions, or executable renderers. Do not submit code intended to execute in another user's browser or attempt to bypass the trusted component registry. Customer content must not falsely suggest certification, regulatory approval, equipment safety, or endorsement by us or a third party.
The first release does not accept arbitrary untrusted executable renderers. If a future feature does, its sandbox and additional terms will be documented before use. A misleading label or visual state that could foreseeably cause serious harm is prohibited.
7. Broadly shared diagrams
Before choosing All SimpleDiagrams users or Anyone with the link (no account required) visibility, remove secrets, personal data, internal hostnames, facility-security details, and information you are not authorised to share. The accountless option is public when anonymous diagram access is enabled in Site settings; it is not a secret or private link. People with access can copy, capture, and redistribute what they see, and restricting access later cannot recall their copies. Broad sharing must not be used for spam, deceptive redirects, malware delivery, impersonation, or unauthorised surveillance. We may apply viewer limits, warnings, or removal to protect users and the Service.
8. Fair use and resource protection
Plan allowances are enforceable limits, not targets that guarantee any traffic pattern is harmless. We may temporarily throttle or block activity that creates unusual load, threatens availability, or indicates attack or error, even if a monthly allowance has not yet been exhausted. We will act proportionately and work with a legitimate Customer to restore safe use where practical.
9. Enforcement
We may investigate suspected violations and preserve relevant evidence. Depending on seriousness, we may warn, remove or restrict content, revoke a credential, throttle a channel, suspend affected access, or terminate under the Terms. We may act immediately where delay could cause material harm, compromise security, violate law, or expose another person's data. Where practical, we will explain the reason and allow cure or appeal.
We may report conduct to authorities where required by law or reasonably necessary to address serious criminal conduct or an imminent threat. Customer remains responsible for costs and third-party claims caused by its material breach as provided in the Terms.
10. Reporting and changes
Report abuse to support@simplediagrams.com with the relevant URL or resource identifier and enough detail to investigate safely. We may update this AUP under the change process in the Terms. A material adverse change will receive the notice required by the Terms.